CVE-2024-56112
- EPSS 0.16%
- Veröffentlicht 16.12.2024 06:15:07
- Zuletzt bearbeitet 05.09.2025 00:30:15
CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.
CVE-2024-53376
- EPSS 89.39%
- Veröffentlicht 16.12.2024 04:15:05
- Zuletzt bearbeitet 05.09.2025 00:33:27
CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.
CVE-2024-54679
- EPSS 2.2%
- Veröffentlicht 05.12.2024 14:15:22
- Zuletzt bearbeitet 05.09.2025 13:39:46
CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.
CVE-2024-51378
- EPSS 93.85%
- Veröffentlicht 29.10.2024 23:15:04
- Zuletzt bearbeitet 07.11.2025 19:02:54
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (...
CVE-2024-51567
- EPSS 94.31%
- Veröffentlicht 29.10.2024 23:15:04
- Zuletzt bearbeitet 07.11.2025 19:02:50
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a ...
CVE-2024-51568
- EPSS 92.47%
- Veröffentlicht 29.10.2024 23:15:04
- Zuletzt bearbeitet 07.07.2025 16:17:23
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacter...
CVE-2019-13056
- EPSS 0.22%
- Veröffentlicht 02.07.2019 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:24:07
An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of the lack of CSRF protection.